Back to Rule

Rule History

SID: 2043101 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 1Dec 29, 2022, 12:00 PM

ET GAMES Multiple Game Cheat Application Related Activity

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET GAMES Multiple Game Cheat Application Related Activity"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"|2f 3f|tqos|3d 7b 22|Head|22 3a 7b 22|Cmd|22 3a|5|7d 2c 22|Body|22 3a 7b 22|QOSRep|22 3a 7b 22|BusinessID|22 3a|1|2c 22|QosNum|22 3a|1|2c 22|QosList|22 3a 5b 7b 22|QosID|22 3a|12418"; startswith; fast_pattern; http.header_names; content:!"Referer"; content:!"User-Agent"; reference:md5,dc058da156fc9a901abc787d1baa32d9; classtype:unknown; sid:2043101; rev:1; metadata:attack_target Client_Endpoint, created_at 2022_12_29, deployment Perimeter, confidence High, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2022_12_29;)

Dec 29, 2022, 12:00 PM

Dec 29, 2022, 12:00 PM

Sep 21, 2024, 3:00 AM

Aug 26, 2025, 9:34 PM

rules/emerging-games.rules